Contents and properties of syslog messages in the CEF format

Information about each detected event is sent immediately after the occurrence of the event as a separate syslog message in the CEF format in UTF-8 encoding.

A CEF message consists of the message body and header.

The CEF message header consists of the following parts:

Fields of the syslog message about an event, which are defined by application options, have the format <key>="<value>". If a key has multiple values, these values are separated with a comma. A colon is used as the separator between keys.

The keys and their values contained in the message depend on the class of the event.

The maximum size of a syslog message about a detected event depends on the values of the syslog settings on the server on which Kaspersky Web Traffic Security is installed. You can only configure syslog messages to a single external syslog server.

Character encoding rules in CEF messages:

In this section:

Classes of events of the Settings group

Classes of events of the Tasks group

Classes of events of the License group

Classes of events of the Update group

Classes of events of the ICAP group

Page top